Vault-Operations-Professional Sample Questions

Vault-Operations-Professional Sample Questions & Answers

Building a production-hardened server setup, including auto-unseal, carries the biggest weight, alongside monitoring telemetry and audit logs, the security model for client introduction, HA and disaster-recovery clustering, HSM benefits, scaling, and ACL policies.

Launch the full Vault-Operations-Professional simulator →

Showing 6 of 12 free samples.

  1. Question 1Advanced

    Create a Working Vault Server Configuration Given a Scenario · Auto unseal Vault

    You need to migrate an existing production Vault cluster from Shamir's Secret Sharing to Auto-Unseal using the Transit Secrets Engine hosted on a separate Vault cluster.

    After configuring the seal stanza in the configuration file, what is the required command sequence to complete the migration?

    Show answer & explanation

    Correct answer: D

    To migrate seals, you first update the configuration file with the new seal stanza. Then you restart the Vault service. Vault will detect a configuration mismatch between the stored barrier and the configuration. You must then run vault operator unseal -migrate and provide the threshold number of existing unseal keys. Vault will decrypt the master key using the old method, re-encrypt it using the new auto-unseal mechanism, and complete the migration.

  2. Question 2Intermediate

    Create a Working Vault Server Configuration Given a Scenario · Enable and configure authentication methods

    You are creating a new AppRole for a CI/CD pipeline. The security team mandates that the SecretID used by the pipeline must be single-use only and must expire after 30 minutes if not used.

    Which command correctly configures the AppRole to meet these requirements?

    Show answer & explanation

    Correct answer: B

    The secret_id_num_uses parameter controls how many times a SecretID can be used to fetch a token; setting it to 1 makes it single-use. The secret_id_ttl parameter sets the expiration of the SecretID itself, meeting the 30-minute requirement.

  3. Question 3Beginner

    Create a Working Vault Server Configuration Given a Scenario · Rekey Vault and rotate encryption keys

    A Vault administrator needs to rotate the encryption key used to protect data at rest (the barrier key).

    What is the correct distinction between vault operator rotate and vault operator rekey?

    Show answer & explanation

    Correct answer: A

    vault operator rotate generates a new encryption key for the storage backend and adds it to the keyring (used for new writes). vault operator rekey is used to generate new unseal keys (shares) or change the threshold required to unseal the vault.

  4. Question 4Intermediate

    Create a Working Vault Server Configuration Given a Scenario · Enable and configure secret engines

    You are tuning a KV secrets engine mounted at secret/. The global default lease TTL is set to 1 hour, and the max lease TTL is 24 hours. You execute the following command:

    vault secrets tune -default-lease-ttl=30m secret/

    When a user subsequently creates a dynamic secret in this engine (if applicable) or a token associated with it, what behavior can they expect regarding the TTL?

    Show answer & explanation

    Correct answer: D

    Mount-specific tuning overrides the global system default configuration. By tuning the secrets engine at secret/ to have a default TTL of 30m, any leases generated specifically by this mount (if it supported dynamic secrets) would default to 30m. Note: KV static secrets don't have leases in the same way dynamic secrets do, but the tuning principle applies to the mount configuration.

  5. Question 5Intermediate

    Create a Working Vault Server Configuration Given a Scenario · Implement integrated storage for Community and Enterprise Vault

    A Vault server is running with Integrated Storage. You need to join a new node to the cluster. The leader is reachable at https://vault-0:8200 (API) and https://vault-0:8201 (Cluster).

    Which command should be executed on the new node to join the cluster?

    Show answer & explanation

    Correct answer: D

    The vault operator raft join command takes the API Address of an existing cluster member (usually the leader), not the Cluster Address. The joining node uses the API to authenticate and receive the Raft configuration information needed to connect via the cluster port (8201) subsequently.

  6. Question 6Intermediate

    Create a Working Vault Server Configuration Given a Scenario · Regenerate a root token

    You have lost the root token for your production Vault cluster and need to generate a new one. The cluster is initialized with a threshold of 3 key shares.

    Which of the following represents the correct sequence of operations?

    Show answer & explanation

    Correct answer: C

    The process is: 1. vault operator generate-root -init (returns a nonce and OTP). 2. vault operator generate-root (provide unseal keys and nonce until threshold is met). 3. Upon reaching threshold, Vault returns the encoded root token. 4. Use the OTP from step 1 to decode the encoded token into the final root token.

Ready for the real thing?

The full Vault-Operations-Professional simulator has every exam-style question, timed mode, and instant scoring.